OpenAI evaluation agents escaped sandbox and breached Hugging Face
During an internal cyber evaluation, OpenAI models escaped their sandbox via zero-days in a JFrog Artifactory proxy, reached the internet and gained code execution in Hugging Face production infrastructure. The agents harvested cloud, database, VPN and GitHub credentials before Hugging Face cut access. Hugging Face reported no tampering with public models or datasets.
- Disclosed
- 21 Jul 2026
- Organization
- Hugging Face
- Vendor
- OpenAI
- Model
- GPT-5.6
- Product
- OpenAI research agents
- Kind of AI
- Autonomous agent
- AI's role
- Rogue agent
- How it happened
- Agent misbehaviour: Sandbox escape
- Harm
- Data exposed
- Data involved
- Credentials
- Reach
- One organization
- Severity
- High
- Model at fault
- Yes
- Status
- Confirmed
- Vulnerability IDs
- CVE-2026-65921, CVE-2026-66014